PT-2025-53686 · Smartertools · Smartermail
Chua Meng Han
·
Published
2025-12-29
·
Updated
2026-05-26
·
CVE-2025-52691
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SmarterTools SmarterMail versions prior to 100.0.9413
SmarterTools SmarterMail versions prior to 9483
Description
An unrestricted upload of files with dangerous types allows an unauthenticated attacker to upload arbitrary files to any location on the mail server. This can potentially enable remote code execution by allowing the attacker to place harmful binaries or web shells on the server that execute with the same permissions as the SmarterMail service. Reconnaissance activity has been detected targeting the API endpoint '/api/v1/licensing/about' to retrieve version information and identify vulnerable instances.
Recommendations
Update SmarterTools SmarterMail to version 100.0.9413 or later.
Update SmarterTools SmarterMail to version 9483 or later.
Implement file upload restrictions and use web application firewalls to minimize the risk of exploitation.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smartermail